Learning/AWS Backend Developer/07 — Hands-on Lab Plan

Hands-on Lab Plan

17 labs (Lab 0 – Lab 16). Every lab is a real AWS resource the learner creates, verifies and then deletes. No screenshot-following; each lab states what it proves.

Mandatory lab structure

Every lab file uses exactly this shape:

## Objective            what you will be able to do afterwards
## Prerequisites        prior labs, tools, IAM permissions needed
## Architecture         Mermaid diagram of what you are about to build
## Steps                numbered, each with the reason it exists
## Commands             copy-pasteable AWS CLI v2 / Maven
## Code                 Java 17 + Spring Boot 3 + AWS SDK v2
## Expected Output      what success actually looks like on screen
## Verification         how you prove it works (not "it didn't error")
## Cleanup              every billable resource, in dependency order
## Common Errors        symptom → cause → fix table
## Production Relevance what changes when this is real traffic

Two rules that are never broken:

  1. Cleanup is not optional. Any lab creating a NAT Gateway, RDS/Aurora instance, ALB, ElastiCache node or Interface Endpoint states its hourly cost up front and its teardown at the end.
  2. No long-lived access keys. After Lab 0, every lab authenticates through a role. An access key pasted into application.yml is treated as a defect, not a shortcut.

The labs

#LabDayTimeBuildsEst. cost if cleaned up
0Account hardening120mMFA on root, admin IAM role, billing alarm, CLI profile$0
1S3 three ways120mOne object uploaded via Console, CLI, and Java SDK v2~$0
2Build the VPC230m3-tier VPC, 2 AZs, IGW, NAT, SGs; private host proven reachable outward, unreachable inward~$1.10 (NAT, 1 day)
3Spring Boot on EC2320mJar deployed, systemd service, reachable via SSM Session Manager~$0.10
4Spring Boot + S3 via instance role315mZero credentials anywhere in the app~$0
5ECS Fargate behind an ALB430mECR image, task def, service, target group, autoscaling, rolling deploy watched live~$0.80
6Lambda in Java520mHandler, client reuse, cold-start measured warm vs cold~$0
7API Gateway → Lambda525mHTTP API, JWT authorizer, throttling proven with a load generator~$0
8Spring Boot + Aurora PostgreSQL630mPrivate subnets, Secrets Manager, HikariCP, Flyway, manual failover observed~$1.50
9DynamoDB with the Enhanced Client720mTable + GSI, bean mapping, a conditional write that blocks a double-update~$0
10ElastiCache cache-aside720mRedis, TTL with jitter, measured hit rate and latency delta~$0.40
11SQS producer/consumer with a DLQ830mDuplicate delivered on purpose, idempotent consumer, DLQ redrive, scale on backlog~$0
12Event-driven fan-out930mEventBridge → (SQS+Lambda) and (Kinesis→Firehose→S3); one consumer fails and is replayed from archive~$0.20
13File upload/download platform1030mPresigned PUT → S3 event → Lambda → DynamoDB metadata; CloudFront signed-URL download; multipart for a large file~$0.10
14Least privilege end to end1125mCloudTrail-derived minimal policy, KMS-encrypted queue + bucket, secret rotation, cross-account AssumeRole~$0.10
15Observability and a real investigation1330mStructured logs, EMF custom metrics, X-Ray traces across an SQS hop, then find an injected latency regression using only telemetry~$0.30
16Capstone: production order platform144–6hEverything, assembled~$3–6

Total in-course lab time: ~6h 15m (already counted inside each day's block budget). Total lab spend if every cleanup is followed: roughly $8–12, plus the capstone.

What each lab proves (the verification, not the steps)

LabThe verification that matters
0aws sts get-caller-identity returns a role session, not a root or long-lived user identity
1The same object is byte-identical whichever of the three paths created it — proving Console, CLI and SDK are one API
2From the private host: curl https://checkip.amazonaws.com succeeds; from your laptop, nc to that host times out at the SG, not the NACL — and you can say which
3The app answers /actuator/health through a port-forwarded SSM session, with no public IP and no SSH key
4Removing every credential from config and rebooting the instance still lists the bucket
5During a rolling deploy, a continuous curl loop records zero failed requests
6Cold invocation vs warm invocation durations differ by the init time you can point to in the log's Init Duration
7The 11th request in a second returns 429 with the throttle headers, and an unsigned request returns 401
8During failover the app throws for N seconds, then recovers — and you can state why N was what it was (DNS TTL + pool eviction)
9Two concurrent conditional writes: exactly one succeeds, the other gets ConditionalCheckFailedException
10Cache hit rate > 90% on the second pass, p99 drops by an order of magnitude, and a deliberately stampeding key is visible in the metrics
11The same message delivered twice produces one row in the outcome table; a poison message lands in the DLQ after exactly maxReceiveCount attempts
12Replay from the EventBridge archive reprocesses only the failed consumer's events, not everyone's
13The presigned URL works before expiry and returns 403 after; a 1 GB upload resumes after being interrupted
14The narrowed policy still passes every happy-path test, and aws s3 ls on an out-of-scope bucket is denied
15You locate the injected latency to a specific subsegment using the service map, before reading any application code
16The full failure drill: kill a task, drop a message, throttle the DB, leak a duplicate — the system still ends in a correct state

Cost-control rules applied to every lab

ResourceRule
NAT GatewayCreated in Lab 2, deleted at end of Day 2, recreated only for labs that need private egress (and each such lab says so)
RDS/AuroraSingle smallest instance; deleted same day; final snapshot skipped deliberately (stated)
ALBOne, shared by Labs 5 and 15; deleted at end of Day 4 unless the learner is continuing to the capstone
ElastiCachecache.t4g.micro, single node, deleted same day
Interface VPC endpointsDemonstrated, then deleted in the same lab (hourly charge per AZ per endpoint)
CloudWatch LogsEvery log group gets an explicit retention (7 days) at creation — never left at "Never expire"
S3Lifecycle rule to abort incomplete multipart uploads after 1 day, set in Lab 13
EverythingTagged Project=aws-course so a single Cost Explorer filter and a single cleanup script can find it all

A cleanup.sh per day and a master teardown checklist ship with the course. The final instruction of Day 14 is to run the master teardown and confirm a $0 forecast.

Labs mapped to the required lab list

The spec named 14 labs; all are covered, several merged or expanded:

Spec labCovered by
S3 upload/downloadLab 1, Lab 13
IAM role and permissionsLab 0, Lab 4, Lab 14
Deploy Spring Boot applicationLab 3, Lab 5
Spring Boot + S3Lab 4
SQS send/receiveLab 11
Asynchronous processingLab 11, Lab 12
LambdaLab 6
API Gateway + LambdaLab 7
Spring Boot + RDSLab 8
DynamoDBLab 9
Redis/ElastiCacheLab 10
Event-driven architectureLab 12
CloudWatch monitoringLab 15
Complete production-style architectureLab 16 (capstone)
(added) NetworkingLab 2
(added) Storage/CDN at scaleLab 13
(added) Security/least privilegeLab 14